Forest of Stones

Privacy Policy

Reference translation. This English text is provided for the convenience of our users. The Korean version is the governing text. Where the two differ, the Korean version applies. See “Governing Language” at the end of this document.

Seonham Labs (the “Company”) treats users’ personal information as important and complies with the laws of the Republic of Korea on the protection of personal information, including the Personal Information Protection Act (「개인정보 보호법」), the Act on Promotion of Information and Communications Network Utilization and Information Protection (the “Network Act”, 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」) and the Protection of Communications Secrets Act (「통신비밀보호법」).

Through this Privacy Policy the Company tells you for what purposes and by what methods the personal information you provide is used, and what measures are taken to protect it.

This Privacy Policy was drawn up in accordance with Article 30 of the Personal Information Protection Act and applies to the “Forest of Stones” service operated by the Company, including the web and the mobile app.

This Privacy Policy may change following amendments to applicable law or guidelines, or a change in the Company’s internal policy. Any change will be announced through the in-app notices (or by individual notification).


1. Items of Personal Information Collected and Methods of Collection

1.1. Items collected

The Company collects only the minimum personal information necessary to provide the Service.

Required items

Items collected on social login

Information generated and collected automatically in the course of using the Service

The Company does not collect advertising identifiers (IDFA on iOS, GAID on Android). See section 8.5 for details.

1.2. Methods of collection


2. Purposes of Collecting and Using Personal Information

In accordance with Articles 15 and 22 of the Personal Information Protection Act and Article 22 of the Network Act, the Company uses the personal information it collects only for the following purposes, and will seek the user’s prior consent if a purpose changes.

2.1. Managing members

2.2. Providing the Service

2.3. Customer support and handling complaints

2.4. Improving and developing the Service

2.5. Operating a safe community


3. Period of Retention and Use of Personal Information

The Company retains and uses a user’s personal information from the date of registration until use of the Service ends.

3.1. On withdrawal of membership

3.2. Retention period for note conversations

The retention period for a note conversation is measured from the time it ends; when the period expires, the conversation and all notes within it are destroyed irrecoverably.

Stage Timing Handling
Automatic ending after no response 10 days from the last note The conversation ends automatically (it can still be viewed)
Viewing period 7 days from the date it ended Retained read-only
Destruction 7 days after the date it ended The conversation and its notes are permanently deleted

3.3. Retention required by law

Where retention for a certain period is required by applicable law, the information is stored separately for that period only and then destroyed.

Act on Consumer Protection in Electronic Commerce

Protection of Communications Secrets Act

Act on Promotion of Information and Communications Network Utilization and Information Protection

3.4. Handling of dormant accounts


4. Procedure and Method for Destroying Personal Information

In accordance with Article 21 of the Personal Information Protection Act and Article 16 of its Enforcement Decree, the Company destroys personal information without delay once the retention period has passed or the purpose of processing has been achieved.

4.1. Procedure

  1. Selection for destruction: selected for destruction as soon as the retention period expires or the purpose of processing is achieved
  2. Choice of method: an appropriate method is chosen according to whether the information is in an electronic file or on paper
  3. Destruction: destroyed irrecoverably by the chosen method
  4. Record: the time of destruction, the person responsible and the method are recorded and managed

Information entered by a user is moved to a separate database once the purpose has been achieved, stored for a certain period in accordance with internal policy and applicable law, and then destroyed. Personal information moved to a separate database is not used for any other purpose except as required by law.

4.2. Methods

Personal information in electronic files

Personal information on paper

4.3. Timing

Case Timing of destruction
Withdrawal of membership Destroyed immediately on withdrawal (the email hash is destroyed automatically after 30 days; information subject to statutory retention is excepted)
Dormant account Permanently deleted one year after conversion to dormant status
End of a statutory retention obligation Destroyed as soon as the retention period ends
Termination of the Service Destroyed within three months of termination

4.4. Exception (retention required by law)

Where retention is required by applicable law, the information is stored separately in a separate database or repository and managed there, and destroyed as soon as the period ends. For the information concerned and the periods, see section 3.


5. Provision of Personal Information to Third Parties

As a rule the Company does not provide users’ personal information to outside parties.

The following are exceptions.

  1. Where the user’s prior consent has been obtained

    • Consent is obtained after stating the recipient, the purpose, the items provided and the retention and use period.
  2. Where required by law, or where an investigative authority makes a request for the purposes of an investigation in accordance with the procedures and methods prescribed by law

    • Where there is a special provision in a statute, such as an urgent need for a criminal investigation
    • Where there is a court warrant, or where the request follows a procedure prescribed by a statute such as the Criminal Procedure Act or the Framework Act on National Taxes

Where personal information is provided to a third party, the Company notifies the user of the following and obtains consent, in accordance with Articles 17 and 18 of the Personal Information Protection Act.


6. Outsourcing of Personal Information Processing

The Company outsources the processing of personal information to external specialist providers as follows in order to provide the Service.

6.1. Providers

1. Cloudflare, Inc.

Outsourced work:

Items of personal information:

Period of retention and use:

Location and contact:

2. Resend, Inc.

Outsourced work:

Items of personal information:

Period of retention and use:

Location and contact:

6.2. Management and supervision of providers

When entering into an outsourcing agreement, the Company sets out the following in writing and manages and supervises the provider so that it processes personal information safely, as required by Article 26 of the Personal Information Protection Act.

  1. A prohibition on processing personal information for any purpose other than the outsourced work
  2. The obligation to take technical and administrative protective measures
  3. Restrictions on sub-contracting
  4. Management and supervision of the provider
  5. Matters concerning liability, including compensation for loss

6.3. Notice of transfer abroad

The providers above are headquartered in the United States, and personal information may be transferred abroad. In the case of Cloudflare, data is processed through data centers in Korea (Seoul, Busan) and its global edge network is used.

Transfer details:

Additional information:

You may refuse the transfer of your personal information abroad, but if you do, your use of Forest of Stones may be restricted.


A user (or, where the user is under 14, their legal representative) may exercise the following rights at any time under Articles 35 to 38 of the Personal Information Protection Act.

7.1. Right to request access (Article 35)

7.2. Right to request correction or deletion (Article 36)

7.3. Right to request suspension of processing (Article 37)

7.5. Right to object to automated decision-making

7.6. Points to note when exercising these rights


8. Installation and Operation of Devices that Collect Personal Information Automatically, and How to Refuse Them

8.1. Use of cookies

The Company uses cookies, which store and retrieve a user’s information from time to time.

What is a cookie?

8.2. Purposes for which cookies are used

8.3. Types and attributes of cookies

Cookie name Purpose Lifetime Attributes
forest_token Stores the access token (API authentication) 15 minutes HttpOnly, Secure, SameSite=Strict
forest_refresh_token Stores the refresh token (token reissue) 7 days HttpOnly, Secure, SameSite=Strict

8.4. How to refuse cookies

You may choose whether cookies are installed.

Browser settings

Limitations if you block cookies

8.5. Tracking and advertising identifiers in the mobile app (not applicable)

The Forest of Stones app does not display advertising and does not collect advertising identifiers.

Earlier editions of this policy (up to the fourth edition) stated that banner advertising was provided through Google AdMob. That function was never actually made available to users, and the related SDK and code have been removed from the app.

If advertising is introduced in future, the Company will amend this policy to give prior notice of the items collected, the purposes and how to refuse, and will follow the consent procedures required by law.

8.6. Push notifications in the mobile app

The Company uses mobile push notifications in order to send service notifications (a new pebble, a note or reply received, notices and the like).

8.7. Access permissions in the mobile app

In accordance with Article 22-2 of the Network Act, the Company gives notice of the access permissions required within a mobile device in order to provide the Service, as follows.

The Forest of Stones app has no required access permissions. Even if you allow none of the optional permissions below, you can use all of the core functions of the Service normally (writing stones, replying with pebbles, note conversations and the like).

Optional access permissions

Permission Purpose When requested If not granted
Notifications (iOS notifications / Android POST_NOTIFICATIONS) Sending service notifications such as a new pebble, a note or reply received, and notices When you choose “Turn on notifications” on the in-app explanation screen, or when you turn notifications on under Settings, then Notification settings Only notifications are not received; there is no restriction on using the Service

Notifications are the only optional permission. App tracking (iOS ATT) and the advertising identifier (Android AD_ID), which appeared in earlier editions of this policy (up to the fourth edition), were removed along with the advertising function — the app no longer shows a tracking consent prompt and does not access an advertising identifier (see section 8.5).

The following are “normal permissions” on Android. They do not access personal information or information stored on the device and are not subject to individual consent.

Permissions not collected

The Company neither requests nor accesses the following permissions, which are not needed to provide the Service.

How to withdraw a permission

You can withdraw a permission you have granted at any time as follows.

Where permissions cannot be set individually because the operating system version is too old, you can obtain individual consent functionality by upgrading through the device manufacturer, or withdraw the permission by deleting the app.


9. Measures to Secure Personal Information

In accordance with Article 29 of the Personal Information Protection Act and the Standards for Measures to Secure Personal Information (a public notice), the Company takes the following measures in order to manage users’ personal information safely.

9.1. Administrative measures

9.2. Technical measures

9.3. Physical measures

9.4. Response to a personal information breach


10. Personal Information Protection Officer and Staff

In accordance with Article 31 of the Personal Information Protection Act, the Company has designated a personal information protection officer as follows, in order to protect users’ personal information and handle complaints relating to it.

Personal information protection officer

Department responsible for personal information protection

How to seek redress

You may raise with the personal information protection officer and the responsible department any enquiry, complaint or request for redress relating to the protection of personal information arising from your use of the Service.

The Company will answer your enquiry promptly and fully. An answer is provided within 10 days of receipt.


11. Advice and Reporting on Infringement of Personal Information

If you need to report an infringement of personal information or seek advice, please contact the bodies below.

Personal Information Infringement Report Center (Korea Internet & Security Agency)

Personal Information Dispute Mediation Committee

Cyber Investigation Division, Supreme Prosecutors’ Office

Cyber Bureau, Korean National Police Agency

Translator’s note — not part of this Privacy Policy. The bodies above serve residents of the Republic of Korea. If you are elsewhere, you may also contact the data protection authority in your own country. Wherever you are, you can write to hello@seonhamlabs.com first.


12. Protection of Children’s Personal Information

Only those aged 19 and over may register with the Company. The Company does not collect the personal information of children under 19.


13. Changes to this Privacy Policy

Content may be added to, deleted from or amended in this Privacy Policy following changes in law, policy or security technology.

13.1. Notice of changes

13.2. Management of the change history


Addendum

Article 1 (Effective date)

This Privacy Policy (fifth edition) takes effect from October 6, 2026. The immediately preceding edition (the fourth) applies from September 22, 2026 to October 5, 2026.

Article 2 (Amendment history)

Fifth edition (effective October 6, 2026; re-notified September 8, 2026)

Fifth edition as first notified (notified August 27, 2026)

Fourth edition (effective September 22, 2026; notified August 23, 2026)

Third edition (effective June 9, 2026)

Second edition (effective May 18, 2026)

First edition (effective March 1, 2026)

Article 3 (Duty to give notice)

Where this Privacy Policy changes, notice is given according to how material the change is, as follows.

Article 4 (Governing law and jurisdiction)

The interpretation and application of this Privacy Policy is governed by the law of the Republic of Korea. A dispute arising between a user and the Company in relation to this Privacy Policy is governed by the law of the Republic of Korea and is subject to the rules on jurisdiction under the Korean Civil Procedure Act.

Translator’s note — not part of this Privacy Policy. The Article above states the governing law and jurisdiction set out in the Korean text. Mandatory data protection rules of your country of residence may nonetheless apply to you. This note is added for readers of this translation and adds nothing to, and takes nothing from, the policy.


Governing Language

This English text is a reference translation provided for the convenience of our users. The Korean version is the governing text. Where there is any difference between the Korean version and this translation, the Korean version applies.

The Korean version is available at forest.seonhamlabs.com/privacy.